Senior GRC Analyst (Security Assurance)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior GRC Analyst (Security Assurance) (Information Security and Compliance): Building and improving governance, risk, and compliance programs for an IoT-enabled industrial technology platform with an accent on ISMS management, security controls, audits, and third-party risk. Focus on aligning practices with ISO 27001/27002, SOC 2, NIST, LGPD, and GDPR while driving remediation, audit readiness, and secure development improvements.
Compensation: Competitive salary and stock options; R$1,035/month meal allowance.
Company
develops integrated industrial hardware and software that helps frontline maintenance workers improve operational efficiency.
What you will do
- Maintain and improve the Information Security Management System in alignment with ISO 27001/27002, SOC 2, and NIST frameworks.
- Perform compliance assessments, control reviews, gap analyses, and remediation tracking.
- Develop and maintain information security policies, standards, procedures, and governance documentation.
- Coordinate internal and external audit evidence, documentation, auditor requests, and continuous audit readiness.
- Support secure development, Privacy by Design, and Privacy by Default practices across Engineering and Product.
- Manage third-party security assessments, customer due diligence questionnaires, controls, evidence, and compliance records.
Requirements
- Background in IT, information security, GRC, internal audit, compliance, or quality management.
- Experience supporting ISMS programs and assessing ISO 27001/27002, SOC 2, and NIST compliance.
- Knowledge of data protection requirements under LGPD and GDPR.
- Experience with internal audits, control reviews, gap analyses, remediation tracking, and security policies.
- Experience with third-party risk management, vendor assessments, and security control validation.
- Advanced English proficiency required. Cross-functional experience with Engineering, IT, Security, Procurement, Legal, and business teams is expected.
Nice to have
- Experience with compliance automation and GRC platforms such as Vanta or Drata.
- Experience working with multiple security frameworks and regulatory environments.
- Experience using Jira, Linear, Monday, or similar platforms for remediation and compliance initiatives.
- Recognized security certifications.
- Experience using automation and AI to improve GRC processes, evidence collection, reporting, and compliance operations.
Culture & Benefits
- Competitive salary and stock options.
- 30 days of paid annual leave.
- Education and courses stipend.
- Health plan with national coverage and no coparticipation, plus dental insurance.
- Wellhub and sports incentive, including an additional R$300 per month for eligible activities.
- Opportunity to earn a trip anywhere in the world every four years.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →